Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
115 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | Uncommon access to Microsoft Teams cookies files Sensitive Microsoft Teams cookies files were accessed. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unknown DLL was added to the AD FS Global Assembly Cache path A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual user account enablement A user enabled an account. This user does not usually enable user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Unusual user account unlock A user unlocked an account. This user does not usually unlock user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | Unusual weak authentication by user A user account authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be indicative of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. | Informational | Identity Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | User account delegation change A user account was modified with delegation to a service. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | User added SID History to an account A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Defense Evasion |
| Analytics | User added to a group and removed A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | User attempted to connect from a suspicious country A user connected from an unusual country. This may indicate the account was compromised. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Resource Development |
| Analytics BIOC | VPN access with an abnormal operating system A user accessed a VPN with an abnormal operating system. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics | VPN login Brute-Force attempt A user account failed to log in to a VPN service multiple times in a short time period. This may indicate a brute-force attack. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Credential Access, Resource Development |
| Analytics BIOC | VPN login by a dormant user A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Defense Evasion |
| Analytics | VPN Login Password Spray An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Credential Access |
| Analytics BIOC | VPN login with a machine account A machine account successfully logged in to a VPN service. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | Vulnerable certificate template loaded A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |